vendor:
ImageMagick-Engine
by:
ABDO10
7.5
CVSS
HIGH
Remote Code Execution (RCE)
78
CWE
Product Name: ImageMagick-Engine
Affected Version From: 1
Affected Version To: 1.7.2004
Patch Exists: NO
Related CWE:
CPE: a:wordpress:imagemagick-engine:1.7.4
Platforms Tested: Windows 10
2022
WordPress Plugin ImageMagick-Engine 1.7.4 – Remote Code Execution (RCE) (Authenticated)
The Wordpress Plugin ImageMagick-Engine version 1.7.4 and earlier is vulnerable to remote code execution. An attacker can exploit this vulnerability by sending a specially crafted payload to the admin-ajax.php file, which allows them to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of the ImageMagick-Engine plugin (1.7.5) or remove the plugin if not needed.